ICO issues data protection guide for cloud users
Watchdog tries to clear up some of the confusion around data protection and processing in the cloud.

The Information Commissioner's Office (ICO) has reminded business leaders of their responsibilities when it comes to safeguarding personal data in the cloud.
The data protection watchdog claims many end users do not realise that the onus is on them to ensure the data they store in the cloud is handled responsibly.
To this end, the ICO has issued guidance, setting out the precautions businesses should take with their data before handing it over to a cloud provider.
Demanding a written contract from Google or Microsoft is unlikely to prove fruitful.
For example, the guidance advises readers to seek assurances from prospective cloud providers about the digital and physical security methods they use to lockdown users data.
It also advises them to have a written contract in place with their chosen provider, which will prevent them from changing the terms of their partnership without prior agreement.
Speaking to IT Pro, Dr Simon Rice, the ICO's technology advisor, said the guidance was produced to help ease some of the concerns data controllers have about embracing cloud.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Over the last six months or so...we've been receiving enquiries from data controllers in the SMB, enterprise and public sector about cloud," said Rice.
"This was our chance to document all the issues that a data controller need to think about before they can move to the cloud," he added.
The ICO regularly fields questions from concerned end users about whether or not they should entrust their data to overseas cloud providers, revealed Rice, which the guidance hopes to address.
"We get a lot of the same questions coming along about security and international transfers," he said. "But we also get more general enquiries from people wanting to know, if we use this system from a cloud provider, what kind of things do I need to take into account?"
Ian Moyse, sales director at cloud-based CRM provider Workbooks.com, welcomed the ICO's attempts to educate users, claiming it should encourage more of them to adopt cloud.
However, the ICO's recommendation that users should obtain a written contract from their chosen cloud provider could prove difficult for many end users to follow through.
"You rarely have this with a software license provider and cloud is seeing rapid and wide customer engagement, which could make this administratively prohibitive," he told IT Pro.
"Demanding a written contract from Google or Microsoft is unlikely to prove fruitful."
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Elizabeth Denham appointed ICO boss
News Denham will be tasked with helping the UK leave the EU without any knock-on effects on privacy
By Clare Hopping
-
Information Commissioner signs off with overview of year
News Christopher Graham has issued a report outlining past achievements and recommendations for the future
By Clare Hopping
-
ICO blasts sluggish speed of EU data law reforms
News Information Commissioner calls for sensible laws when it comes to personal data
By Joe Curtis
-
Digital marketing firm hit with £50k nuisance calls fine from ICO
News Reactiv Media apologises for making marketing calls to TPS members, and claims they were made in error
By Caroline Donnelly
-
UK TPS users still receive nuisance calls, research shows
News Ofcom nuisance calls research shows TPS sign-ups leads to users receiving a third fewer calls
By Caroline Donnelly
-
Cabinet Office rapped for slow FOI request response times
News Government department blames uptick in requests caused by Jimmy Saville and Margaret Thatcher for delays
By Caroline Donnelly
-
Home Office under scrutiny over FOI response times
News Sussex Police and Tyneside Council also subject to monitoring by ICO
By Jane McCallion
-
UPDATED: Government departments rapped for slow response to FOI requests
News The Information Commissioner's Office places four public authorities under surveillance for three months next year.
By Caroline Donnelly